Privacy Policy
Last updated:
- General
- Who we are and our Data Protection Officer
- What information we collect
- How we use the information
- Legal basis for processing and Amendment 13
- Who we share information with
- Direct marketing communications
- Automated decisions and profiling
- Cookies and tracking technologies
- Children's privacy
- How long we keep the information
- Data security
- Security incidents and notification
- Your rights
- International data transfers
- Changes to this policy
- Contact
1. General
affilink ("the Service", "we", "the Platform") is an affiliate marketing platform that lets businesses launch and manage affiliate programs, and lets affiliates promote offers and earn a commission. We respect your privacy and are committed to protecting the personal data you provide. This policy explains what information we collect, how we use it, who we share it with, and what rights you have. This policy is aligned with the Israeli Privacy Protection Law, 5741-1981, including Amendment No. 13 to the Law.
Using the Service constitutes acceptance of this policy.
2. Who we are and our Data Protection Officer
The Service is operated by Eyal Meshulam (VAT-exempt dealer), dealer no. 034162560, of 57 HaTichon St., Haifa (the "Operator"). The Operator is the Controller of the personal data processed through the Service.
Data Protection Officer (DPO): We have appointed a Data Protection Officer, Eyal Meshulam, responsible for implementing this policy and handling privacy-related requests. You may contact the DPO directly at dpo@affilink.co.il.
3. What information we collect
Information you provide to us
- Account details: name, email address and password on registration. If you sign up with Google, we receive your name and email from your Google account.
- Organization details: business name, details of team members you invite, and the settings of offers you create.
- Billing and payment details: when you purchase a subscription, payment takes place on a secure Green Invoice / morning payment page, and billing details are processed by them and by the clearing provider behind them. We do not store card details on our servers, and we never see them.
- Affiliate payout details: details required to pay commissions (e.g. bank account or payment method), as provided for settlement.
- Content you generate: tracking links, campaign settings and support requests.
Information collected automatically
- Affiliate tracking data (Server-to-Server): clicks and conversions reported through our tracking system, including click identifiers, IP address, device type and referring page. This data is essential to the Service's core function - conversion attribution and commission payment.
- Usage and analytics data: IP address, browser type, pages viewed and access times - collected via Google Analytics only if you allowed it (see the cookies section).
- Cookies and local storage: for session management, theme preference and security.
4. How we use the information
- To provide and operate the Service - registration, account management, link generation and conversion attribution.
- To calculate, report and pay commissions and manage subscription billing.
- To secure the platform, prevent fraud and detect abuse.
- To improve the Service and analyze usage patterns (in aggregate).
- To communicate with you - operational updates, support and service notices.
- To comply with legal obligations (e.g. accounting and tax).
5. Legal basis for processing and Amendment 13
We process personal data on one or more of the following bases: performance of our contract with you (providing the Service), your consent, legitimate interest (security, fraud prevention and service improvement), and legal obligation. Processing is carried out in accordance with the Privacy Protection Law, 5741-1981, including Amendment No. 13 and its regulations.
Consequences of withholding consent: providing some information is essential to operate the Service (e.g. account details and conversion attribution) - without it we cannot provide the Service or parts of it. Providing other information (e.g. consent to marketing) is optional, and withholding it will not affect your ability to use the Service.
6. Who we share information with
We do not sell personal data. We share information only in the following cases:
- Service providers (data processors): Cloudflare (hosting and infrastructure), Google (authentication, and Analytics if you allowed it), and Green Invoice / morning (issuing invoices and receipts, and clearing payment for the subscription and platform fees) - each only to the extent required for its role.
- Between parties to a transaction: a business and an affiliate sharing a conversion will see the data required to settle between them (e.g. conversion volume and commissions), but not personal details beyond what is necessary.
- As required by law: where required by law, court order, or to protect our rights.
7. Direct marketing communications
Subject to your consent, we may send you promotional material and marketing updates by email, SMS or other means, in accordance with the Communications Law (Telecommunications and Broadcasting), 5742-1982. You may withdraw your consent and stop receiving promotional material at any time, via the opt-out mechanism in each message or by contacting us. Service messages essential to operating your account (verification, billing, security alerts) may be sent even without marketing consent.
8. Automated decisions and profiling
For security and fraud prevention, we may analyze click and conversion patterns and apply automated checks to detect anomalous activity. We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects on you without the possibility of human review. If you believe a particular decision was made unlawfully, you may contact us for reconsideration.
9. Cookies and tracking technologies
We use essential cookies (authentication and security) and preference cookies (theme), which are always active. We also use an analytics tool (Google Analytics), which is loaded only after you give explicit consent in the cookie banner; until you approve, and if you choose "Necessary only", the tool is not loaded at all and no data is sent to it. You can change or withdraw your consent at any time via the "Cookie settings" link at the bottom of every page. Full details appear in our Cookie Policy.
10. Children's privacy
The Service is intended for users aged 18 and over and for corporations, and is not directed at minors. We do not knowingly collect personal data from minors. If you become aware that a minor has provided us with information, please contact us and we will act to delete it.
11. How long we keep the information
We retain personal data for as long as your account is active, and for an additional period as required to meet legal obligations (e.g. retaining accounting records under tax law), resolve disputes and enforce agreements. When an account is deleted, we delete or anonymize data we no longer need to retain.
12. Data security
We apply reasonable technical and organizational measures to protect the information, including encryption in transit (HTTPS), HMAC signatures on conversion reports, role-based access control, and encrypted secret management. However, no system is entirely immune, and we cannot guarantee absolute security.
13. Security incidents and notification
We monitor our systems to detect security incidents. In the event of a serious security incident affecting personal data, we will act in accordance with our legal obligations - including notifying the Privacy Protection Authority and the relevant data subjects as required, covering the nature of the incident, its scope and the steps taken to mitigate harm.
14. Your rights
Subject to applicable law, you have the following rights:
- Access: to receive information about data held about you.
- Rectification: to request correction of inaccurate or outdated information.
- Erasure: to request deletion of information, subject to exceptions in law.
- Restriction and objection: to object to certain processing, including marketing.
To exercise your rights, contact the Data Protection Officer at dpo@affilink.co.il. We will respond within a reasonable time and in accordance with the law. You also have the right to lodge a complaint with the Privacy Protection Authority.
15. International data transfers
Some of our service providers (e.g. Cloudflare and Google) process data on servers outside Israel. Such transfers are carried out in accordance with the Privacy Protection Regulations (Transfer of Data to Databases Abroad) and subject to the providers' commitment to an adequate level of protection.
16. Changes to this policy
We may update this policy from time to time. The current version will be published on this page with an updated date. A material change will be brought to your attention by reasonable means.
17. Contact
For any question or request regarding your privacy and personal data, you may contact our Data Protection Officer, Eyal Meshulam, at dpo@affilink.co.il.